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~ The MAILING DATE of this communication appears on the cover sheet with the correspondence address- 

All claims being allowable, PROSECUTION ON THE MERITS IS (OR REMAINS) CLOSED in this application. If not included 
herewith (or previously mailed), a Notice of Allowance (PTOL-85) or other appropriate communication will be mailed in due course. THIS 
NOTICE OF ALLOWABILITY IS NOT A GRANT OF PATENT RIGHTS. This application is subject to withdrawal from issue at the initiative 
of the Office or upon petition by the applicant. See 37 CFR 1.313 and MPEP 1308. 

1 . This communication is responsive to an amendment filed 1 1/30/09 . 

2. The allowed claim(s) is/are 1,3-7,12-14,16-20,25-31,33-41,44,47,49 and 50 . 

3. □ Acknowledgment is made of a claim for foreign priority under 35 U.S.C. § 119(a)-(d) or (f). 

a) □ All b)DSome* c) □ None of the: 

1. □ Certified copies of the priority documents have been received. 

2. □ Certified copies of the priority documents have been received in Application No. . 

3. □ Copies of the certified copies of the priority documents have been received in this national stage application from the 

International Bureau (PCT Rule 17.2(a)). 
* Certified copies not received: . 

Applicant has THREE MONTHS FROM THE "MAILING DATE" of this communication to file a reply complying with the requirements 
noted below. Failure to timely comply will result in ABANDONMENT of this application. 
THIS THREE-MONTH PERIOD IS NOT EXTENDABLE. 

4. □ A SUBSTITUTE OATH OR DECLARATION must be submitted. Note the attached EXAMINER'S AMENDMENT or NOTICE OF 

INFORMAL PATENT APPLICATION (PTO-152) which gives reason(s) why the oath or declaration is deficient. 

5. □ CORRECTED DRAWINGS ( as "replacement sheets") must be submitted. 

(a) □ including changes required by the Notice of Draftsperson's Patent Drawing Review ( PTO-948) attached 

1 ) □ hereto or 2) □ to Paper No./Mail Date . 

(b) □ including changes required by the attached Examiner's Amendment / Comment or in the Office action of 

Paper No./Mail Date . 

Identifying indicia such as the application number (see 37 CFR 1. 84(c)) should be written on the drawings in the front (not the back) of 
each sheet. Replacement sheet(s) should be labeled as such in the header according to 37 CFR 1.121(d). 

6. □ DEPOSIT OF and/or INFORMATION about the deposit of BIOLOGICAL MATERIAL must be submitted. Note the 

attached Examiner's comment regarding REQUIREMENT FOR THE DEPOSIT OF BIOLOGICAL MATERIAL. 
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EXAMINER'S AMENDMENT 

1 . An examiner's amendment to the record appears below. Should the changes and/or additions be 
unacceptable to applicant, an amendment may be filed as provided by 37 CFR 1.312. To ensure 
consideration of such an amendment, it MUST be submitted no later than the payment of the issue fee. 

Authorization for this examiner's amendment was given in a telephone interview with Kevin Zilka 
on 1/12/10. 

The application has been amended as follows: 

IN THE CLAIMS : 

1 . (Currently Amended) A network adapter system, comprising: 

a processor positioned on a network adapter coupled between an end-point 
computer and a network, the network adapter capable of being installed on the end-point computer; 

wherein the processor is adapted for virus scanning and content scanning of 
network traffic transmitted between the end-point computer and the network, the content 
scanning including scanning for unwanted content other than viruses; 

wherein the system is operable such that the virus scanning utilizes virus signature files to scan 
for known types of malicious programs or data; 

wherein the system is operable such that the virus signature files are stored on non-volatile solid 
state memory on the network adapter; 

wherein the processor is user-configured; 

wherein the processor determines whether received packets are of interest, passes 
the received packets that are not of interest to the end-point computer, and scans the 
received packets that are of interest; 

wherein the system is operable such that a predetermined amount of the received packets are 
assembled for determining whether the received packets are of interest, the received packets including 
packets received at the network adapter; 

wherein the system is operable such that if the received packets that are of interest fail the 
scanning, an alert is displayed which provides remedy options; 

wherein the system is operable such that the received packets are of interest based on an 
associated protocol; 

wherein the system is operable such that the received packets that are not of interest bypass the 
scanning; 
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wherein the system is operable such that scanning the received packets that are of interest is 
prioritized based on a file type associated with the received packets[[.]] ; 

wherein the bypassing of the scanning includes bypassing a scanner and random access 
memory (RAM) of the processor, and communicating directly with a network driver of the end-point 
computer. 



14. (Currently Amended) A method for scanning network traffic on a network 
adapter, comprising: 

receiving packets at a network adapter including a processor positioned thereon, 
the network adapter installed on an end-point computer; 

virus scanning and content scanning of the packets utilizing the processor, the 
content scanning including scanning for unwanted content other than viruses; and 

conditionally taking security measures if the packets fail the scan; 

wherein the virus scanning utilizes virus signature files to scan for known types of 
malicious programs or data; 

wherein the virus signature files are stored on non-volatile solid state memory on 
the network adapter; 

wherein the processor is user-configured; 

wherein the processor determines whether the received packets are of interest, 
passes the received packets that are not of interest to the end-point computer, and scans 
the received packets that are of interest; 

wherein a predetermined amount of the received packets are assembled for 
determining whether the received packets are of interest, the received packets including 
packets received at the network adapter; 

wherein if the received packets that are of interest fail the scanning, an alert is 
displayed which provides remedy options; 

wherein the received packets are of interest based on an associated protocol; 

wherein the received packets that are not of interest bypass the scanning; 

wherein scanning the received packets that are of interest is prioritized based on a file type 
associated with the received packets[[.]] ; 

wherein the bypassing of the scanning includes bypassing a scanner and random access 
memory (RAM) of the processor, and communicating directly with a network driver of the end-point 
computer. 
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27. (Currently Amended) A system, comprising: 

network adapter means for receiving packets, the network adapter means installed 
on an end-point computer; 

processor means positioned on the network adapter means for virus scanning and 
content scanning of the packets, the content scanning including scanning for unwanted content other than 
viruses; and 

means for conditionally taking security measures if the packets fail the scan; 

wherein the system is operable such that the virus scanning utilizes virus signature files to scan 
for known types of malicious programs or data; 

wherein the system is operable such that the virus signature files are stored on non-volatile solid 
state memory on the network adapter means; 

wherein the processor means is user-configured; 

wherein the processor means determines whether the received packets are of 
interest, passes the received packets that are not of interest to the end-point computer, and 
scans the received packets that are of interest; 

wherein the system is operable such that a predetermined amount of the received packets are 
assembled for determining whether the received packets are of interest, the received packets including 
packets received at the network adapter means; 

wherein the system is operable such that if the received packets that are of interest fail the 
scanning, an alert is displayed which provides remedy options; 

wherein the system is operable such that the received packets are of interest based on an 
associated protocol; 

wherein the system is operable such that the received packets that are not of interest bypass the 
scanning; 

wherein the system is operable such that scanning the received packets that are of interest is 
prioritized based on a file type associated with the received packets[[.]] ; 

wherein the bypassing of the scanning includes bypassing a scanner and random access 
memory (RAM) of the processor, and communicating directly with a network driver of the end-point 
computer. 



28. (Currently Amended) A system, comprising: 

network adapter means for receiving packets, the network adapter means being 
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installed on an end-point computer; 

logic positioned on the network adapter means for virus scanning and content 
scanning of the packets, the content scanning including scanning for unwanted content 
other than viruses; and 

logic for conditionally taking security measures if the packets fail the scan; 

wherein the system is operable such that the virus scanning utilizes virus signature files to scan 
for known types of malicious programs or data; 

wherein the system is operable such that the virus signature files are stored on non-volatile solid 
state memory on the network adapter means; 

wherein the logic is user-configured; 

wherein the logic determines whether the received packets are of interest, passes 
the received packets that are not of interest to the end-point computer, and scans the 
received packets that are of interest; 

wherein the system is operable such that a predetermined amount of the received packets are 
assembled for determining whether the received packets are of interest, the received packets including 
packets received at the network adapter means; 

wherein the system is operable such that scanning the received packets that are of interest is 
prioritized based on a file type associated with the received packets; 

wherein the system is operable such that the received packets are of interest based on an 
associated protocol; 

wherein the system is operable such that the received packets that are not of interest bypass the 
scanning [[.]] ; 

wherein the bypassing of the scanning includes bypassing a scanner and random access 
memory (RAM) of the processor, and communicating directly with a network driver of the end-point 
computer. 



29. (Currently Amended) A network adapter system, comprising: 

a processor positioned on a network adapter coupled between an end-point 

computer and a network, the processor including a packet assembly module, random 

access memory (RAM), and a scanner module, the network adapter being installed on the 

end-point computer; and 

a user interface driver for identifying network traffic of interest transmitted 

between the end-point computer and the network; 

wherein the processor is adapted for discerning and virus scanning and content 
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scanning of network traffic of interest transmitted between the end-point computer and 
the network, the content scanning including scanning for unwanted content other than 
viruses; 

wherein the system is operable such that the virus scanning utilizes virus signature files to scan 
for known types of malicious programs or data; 

wherein the system is operable such that the virus signature files are stored on non-volatile solid 
state memory on the network adapter; 

wherein the network adapter receives the network traffic; 

wherein the processor is user-configured; 

wherein the processor determines whether the received network traffic is of 
interest, passes the received network traffic that is not of interest to the end-point 
computer, and scans the received network traffic that is of interest; 

wherein the system is operable such that a predetermined amount of the received network traffic 
is assembled for determining whether the received network traffic is of interest, the received network 
traffic including network traffic received at the network adapter; 

wherein the system is operable such that scanning the received network traffic of interest is 
prioritized based on a file type associated with the received network traffic; 

wherein the system is operable such that the received network traffic is of interest based on an 
associated protocol; 

wherein the system is operable such that the received network traffic that is not of interest 
bypasses the scanning[[.]] ; 

wherein the bypassing of the scanning includes bypassing a scanner and the RAM of the 
processor, and communicating directly with a network driver of the end-point computer. 

48. (Cancelled) 

2. The following is an examiner's statement of reasons for allowance: The prior art does not teach 
nor render obvious each and every limitation of the claimed invention. Specifically the prior art does not 
teach a network adapter with a processor for scanning viruses that is to be installed on an end-point 
computer and the processor is adapted for virus scanning and content scanning of network traffic 
transmitted between the end-point computer and the network, the content scanning including scanning for 
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unwanted content other than viruses and the received packets are of interest based on an associated 
protocol wherein the received packets that are not of interest bypass the scanning and scanning the 
received packets that are of interest is prioritized based on a file type associated with the received 
packets and bypassing the scanning includes bypassing a scanner and random access memory of the 
processor and communicating directly with a network driver of the end-point computer. 

Any comments considered necessary by applicant must be submitted no later than the payment 
of the issue fee and, to avoid processing delays, should preferably accompany the issue fee. Such 
submissions should be clearly labeled "Comments on Statement of Reasons for Allowance." 

Any inquiry concerning this communication or earlier communications from the examiner should 
be directed to PHILIP J. CHEA whose telephone number is (571 )272-3951 . The examiner can normally 
be reached on M-F 6:30-4:00 (1st Friday Off). 

If attempts to reach the examiner by telephone are unsuccessful, the examiner's supervisor, 
Joseph Thomas can be reached on 571-272-6776. The fax phone number for the organization where this 
application or proceeding is assigned is 571-273-8300. 

Information regarding the status of an application may be obtained from the Patent Application 
Information Retrieval (PAIR) system. Status information for published applications may be obtained from 
either Private PAIR or Public PAIR. Status information for unpublished applications is available through 
Private PAIR only. For more information about the PAIR system, see http://pair-direct.uspto.gov. Should 
you have questions on access to the Private PAIR system, contact the Electronic Business Center (EBC) 
at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative 
or access to the automated information system, call 800-786-9199 (IN USA OR CANADA) or 571-272- 
1000. 

Philip J Chea 
Examiner 
Art Unit 2453 

/Philip J Chea/ 
Examiner, Art Unit 2453 
1/12/10 



